PkgRadar

npm · registry.npmjs.org

edge-currency-accountbased

Remote Dependency Spec: dependencies.@fioprotocol/fiosdk="https://github.com/EdgeApp/fiosdk_typescript.git#47df5818442edec69b735d6a723747aad33b8d71"

Why PkgRadar flagged 4.80.0-1

SeveritySignalEvidence
highRemote Dependency Specdependencies.@fioprotocol/fiosdk="https://github.com/EdgeApp/fiosdk_typescript.git#47df5818442edec69b735d6a723747aad33b8d71" · package.json
highRemote Dependency Specdependencies.@zano-project/zano-utils-js="https://github.com/EdgeApp/zano-utils-js/releases/download/v0.0.4-edge.1/zano-project-zano-utils-js-0.0.4.tgz" · package.json
highNew Remote Dependency Vs Previousdependencies.@zano-project/zano-utils-js added in 4.80.0-1 vs 4.79.1: "https://github.com/EdgeApp/zano-utils-js/releases/download/v0.0.4-edge.1/zano-project-zano-utils-js-0.0.4.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.80.0-1High risk362026-06-12
4.83.0Review32026-06-12
4.82.0Review102026-05-28
4.82.1Review62026-05-28

Block this in CI

PkgRadar gates edge-currency-accountbased (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]